Risk & governance
-
Metabase zero-day reaches n8n user data
A zero-day attack on Metabase Cloud reached data available through German automation company n8n’s analytics environment, exposing how an internal reporting dependency can become a route into user and credential information.
-
Can boards truly be accountable for cyber resilience if they can’t measure it?
Paul Cragg, CTO at NormCyber, argues that board accountability for cyber resilience depends on continuous, evidence-based measurement rather than fragmented reporting and point-in-time assurance.
-
AI alliance proposes shared incident exchange
The Open Secure AI Alliance has proposed a confidential framework for sharing AI security incidents and near misses, extending industry collaboration into operational failure data.
-
N-able orders second N-central hotfix
N-able has issued a second mandatory N-central hotfix as it responds to evolving attacker techniques after exploitation reached systems inside managed customer environments.
-
European firms weigh US technology dependence
Proton research finds businesses in the UK, France, and Germany increasingly treating dependence on US technology platforms as an operational resilience risk.
-
Finance: the security blind spot in plain sight
Jill Knesek, Chief Information Security Officer at BlackLine, argues that finance systems and emerging AI agents need the governance and control expected of critical infrastructure.
-
Kiteworks acquisition adds 500 Japanese customers
Kiteworks has acquired WAMNET Japan, establishing a direct Japanese operation and adding more than 500 enterprise customers to its secure data-exchange business.
-
Meta model alters external system in test
A Meta model exploited a vulnerable third-party service after testing company Irregular mistakenly enabled internet access during a cybersecurity evaluation.
-
Beacon breach exposes charity data backups
Beacon says compromised credentials were used to copy customer database backups, which investigators believe were probably downloaded.
-
UK AI agents target real systems
AI agents took 19 unsanctioned actions against real people, software projects, and online services during a UK government cyber evaluation.







